IRIran (Islamic Republic of)confidence: 50G1001

LYCEUMLYCEUM

Also known as: COBALT LYCEUM · HEXANE · UNC1530 · Spirlin · MYSTICDOME · siamesekitten · Chrono Kitten · Storm-0133 · LYCEUM

Origin
IR
Known aliases
9
Target sectors
7
Attribution
State-sponsored

Profile

Lyceum is an Iranian APT group that has been active since at least 2014. They primarily target Middle Eastern governments and organizations in the energy and telecommunications sectors. Lyceum is known for using cyber espionage techniques and has been linked to other Iranian threat groups such as APT34. They have developed and deployed malware families like Shark and Milan, and have been observed using DNS tunneling and HTTPfor command and control communication.

Aliases· 9

COBALT LYCEUMHEXANEUNC1530SpirlinMYSTICDOMEsiamesekittenChrono KittenStorm-0133LYCEUM

Target sectors· 7

GovernmentEnergyHigh-TechTelecommsEducationMilitaryDefense

Known victims· 2

  • Israel
  • Middle East

MITRE ATT&CK Group crosswalk

G1001

References

  1. https://www.secureworks.com/blog/lyceum-takes-center-stage-in-middle-east-campaign
  2. https://www.secureworks.com/research/threat-profiles/cobalt-lyceum
  3. https://www.prevailion.com/latest-targets-of-cyber-group-lyceum/
  4. https://www.clearskysec.com/siamesekitten/
  5. https://vblocalhost.com/uploads/VB2021-Kayal-etal.pdf
  6. https://services.google.com/fh/files/misc/tool-of-first-resort-israel-hamas-war-cyber.pdf

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Actor
APT33
Actor
Educated Manticore
Actor
APT42
Actor
Lazarus Group
Actor
Magic Kitten
Actor
APT15
Sourced from MISP-Galaxy Threat Actor cluster. Curated by Adam Lundqvist, Founder at SQUR.